CVE-2026-68150: fs/super: fix emergency thaw double-unlock of s_umount
In the Linux kernel, the following vulnerability has been resolved:
fs/super: fix emergency thaw double-unlock of sumount
dothawall() iterates over all superblocks via iteratesupers() with SUPERITEREXCL, which acquires sumount exclusively before calling the callback and releases it afterwards. However, the callback dothawallcallback() calls thawsuperlocked() which unconditionally releases sumount on every code path. This results in a second unlock attempt in iteratesupers() that corrupts the rwsem state, triggering a DEBUGRWSEMS warning:
[ 182.601148] sysrq: Emergency Thaw of all frozen filesystems [ 182.601865] ------------[ cut here ]------------ [ 182.602375] DEBUGRWSEMSWARNON((rwsemowner(sem) != current) && !rwsemtestoflags(sem, RWSEMNONSPINNABLE)): count = 0x0, magic = 0xffff99b1011e5870, owner = 0x0, curr 0xffff99b101b06c80, list not empty [ 182.603817] WARNING: kernel/locking/rwsem.c:1412 at upwrite+0xa3/0x170, CPU#2: kworker/2:1/53 [ 182.604578] Modules linked in: [ 182.604864] CPU: 2 UID: 0 PID: 53 Comm: kworker/2:1 Not tainted 7.2.0-rc4-00001-gbd3bd93ea98a-dirty #4 PREEMPT(lazy) [ 182.605711] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.13.0-1kylin1 04/01/2014 [ 182.606417] Workqueue: events dothawall [ 182.606750] RIP: 0010:upwrite+0xaf/0x170 [ 182.607076] Code: 19 3a 92 48 0f 44 c2 48 8b 55 08 48 8b 55 00 4c 8b 45 08 48 8b 55 00 48 8d 3d ad 91 e0 01 48 8b 4d 20 50 48 c7 c6 f0 8c 26 92 <67> 48 0f b9 3a e8 d7 93 4e 00 58 eb 81 48 83 7f 18 00 48 c7 c2 8d [ 182.608563] RSP: 0018:ffffb670001d7e08 EFLAGS: 00010246 [ 182.609007] RAX: ffffffff92349e8d RBX: 0000000000000000 RCX: ffff99b1011e5870 [ 182.609595] RDX: 0000000000000000 RSI: ffffffff92268cf0 RDI: ffffffff92914d10 [ 182.610283] RBP: ffff99b1011e5870 R08: 0000000000000000 R09: ffff99b101b06c80 [ 182.610847] R10: ffff99b10139a808 R11: fefefefefefefeff R12: 0000000000000000 [ 182.611414] R13: ffffffff90cf74d0 R14: 0000000000000000 R15: ffff99b1011e5800 [ 182.612009] FS: 0000000000000000(0000) GS:ffff99b1eaaee000(0000) knlGS:0000000000000000 [ 182.612670] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [ 182.613146] CR2: 00000000005c631c CR3: 00000000013ee000 CR4: 00000000000006f0 [ 182.613722] Call Trace: [ 182.613946] <TASK> [ 182.614130] iteratesupers+0x128/0x150 [ 182.614463] dothawall+0x1b/0x30 [ 182.614759] processscheduledworks+0xbb/0x3f0 [ 182.615150] ? pfxworkerthread+0x10/0x10 [ 182.615499] workerthread+0x129/0x270 [ 182.615816] ? pfxworkerthread+0x10/0x10 [ 182.616201] kthread+0xe2/0x120 [ 182.616469] ? pfxkthread+0x10/0x10 [ 182.616792] retfromfork+0x15b/0x240 [ 182.617115] ? pfxkthread+0x10/0x10 [ 182.617426] retfromforkasm+0x1a/0x30 [ 182.617761] </TASK> [ 182.617968] ---[ end trace 0000000000000000 ]--- [ 182.618412] Emergency Thaw complete
Fix this by switching to SUPERITERUNLOCKED and acquiring sumount in the callback via superlockexcl() before calling thawsuperlocked(). This matches the locking pattern expected by thawsuperlocked() and eliminates the double unlock.
While at it, remove the dead 'return;' at the end of dothawallcallback().
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Linux kernelto a version that resolves this vulnerability.Fixed in 7.2.0-rc4-00001-gbd3bd93ea98a-dirty - Configuration
In fs/super, adjust the emergency-thaw iteration to use SUPER_ITER_EXCL (exclusive s_umount acquisition). This matches the locking pattern expected by the thaw callback and prevents the double-unlock/corruption of rwsem state that triggers DEBUG_RWSEMS_WARN_ON.
Linux kernel (fs/super) SUPER_ITER_EXCL / SUPER_ITER_UNLOCKED = use SUPER_ITER_EXCL (acquire s_umount exclusively before iterating) - Configuration
In the fs/super emergency thaw implementation, ensure thaw_super_locked() is used to handle the unlocking so that s_umount is not double-unlocked in a second unlock attempt in __iterate_supers(); eliminate the dead/incorrect unlock that leads to corrupted rwsem state and the warning in kernel/locking/rwsem.c (up_write).
Linux kernel (fs/super) thaw_super_locked() / double-unlock behavior = remove the second unlock path and make thaw_super_locked() unconditionally release s_umount on every code path
Event History
Frequently Asked Questions
What is the severity of CVE-2026-68150?
The severity of CVE-2026-68150 is rated as 22.
What does CVE-2026-68150 affect?
CVE-2026-68150 affects the Linux kernel, specifically related to the emergency thaw operation of superblocks.
How does CVE-2026-68150 impact Linux kernel security?
CVE-2026-68150 can lead to a potential double-unlock scenario in the handling of superblocks, which may affect system stability.
How do I fix CVE-2026-68150?
To fix CVE-2026-68150, ensure that you apply the latest patches provided for the Linux kernel.
When was CVE-2026-68150 published?
CVE-2026-68150 was published on August 10, 2026.